On March 4, 2026, the dental practice paolidental.org appeared on the LockBit 5 ransomware leak site with internal files listed as exfiltrated. The breach affects patients and staff whose personal and medical information may have been taken, even though the exact number of individuals impacted remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that LockBit 5 operators added paolidental.org to their data-leak page on March 4, 2026. The group claims to have stolen internal files during a ransomware attack on the practice. No precise victim count has been published, and the precise data types remain limited in early descriptions to “internal files.” The practice’s own website describes a team with more than 30 years of combined experience, suggesting a long-established patient base whose records could now be at risk.
Why This Matters for You and Your Family
When a local dental office is hit, the consequences reach far beyond the clinic. Medical and dental records often contain names, addresses, dates of birth, Social Security numbers, insurance details, and treatment histories. Once stolen, this information can be sold, used for identity theft, or combined with other leaks to build a complete profile of you and your family. Even if you were not a current patient, older records or family members treated years ago may still be included. The sudden public listing gives thieves a head start before most people learn their data has moved.
The Doxxing and Identity-Chain Risks
Credential leaks from one service frequently cascade into account takeovers elsewhere. A password or email address taken from a dental-practice system can unlock linked accounts on email, banking, or social media. Gaming accounts belonging to children are especially vulnerable because they often reuse the same credentials or are tied to a parent’s email. These connections create doxxing chains that expose home addresses, phone numbers, and family relationships. Available reporting describes how ransomware groups increasingly publish or sell such data to accelerate extortion and embarrassment.